CRITICAL10.0CVE-2026-30966Parse Server role escalation and CLP bypass via direct `_Join` table write from 0, < 8.6.20, >= 9.0.0, < 9.5.2
CRITICAL10.0CVE-2024-27298Parse Server literalizeRegexPart SQL Injection from 0, < 6.5.0
from 0, < 4.10.7
CRITICAL9.8ZDI-CAN-23894: Parse Server literalizeRegexPart SQL Injection Authentication Bypass Vulnerability
from 0, < 7.2.0
CRITICAL9.8Parse Server vulnerable to remote code execution via MongoDB BSON parser through prototype pollution
from 0, < 5.5.2, >= 6.0.0, < 6.2.1
CRITICAL9.8Parse Server vulnerable to Remote Code Execution via prototype pollution in MongoDB BSON parser
from 0, < 4.10.18, >= 5.0.0, < 5.3.1
CRITICAL9.1Parse Server: Auth provider validation bypass on login via partial authData
from 0, < 8.6.52, >= 9.0.0, < 9.6.0
CRITICAL9.0Parse Server crash and RCE via invalid Cloud Function or Cloud Job name
from 0, < 6.5.5
HIGH8.7Parse Server is vulnerable to authentication bypass via spoofing
from 0, < 5.4.1
HIGH8.6Parse Server vulnerable to brute force guessing of user sensitive data via search patterns
from 0, < 4.10.14, >= 5.0.0, < 5.2.5
HIGH8.6Authentication bypass in Parse Server Apple Game Center auth adapter
from 0, < 4.10.11, >= 5.0.0, < 5.2.2
HIGH8.2Protected fields exposed via LiveQuery in parse-server
from 0, < 4.10.13, >= 5.0.0, < 5.2.4
HIGH8.1Parse Server's custom object ID allows to acquire role privileges
from 0, < 7.3.0
HIGH7.7Parse Server stores password in plain text
from 0, < 4.5.0
HIGH7.5Parse Server: LiveQuery subscription query depth bypass
from 0, < 8.6.56, >= 9.0.0, < 9.6.0
HIGH7.5Parse Server: Query condition depth bypass via pre-validation transform pipeline
from 0, < 8.6.55, >= 9.0.0, < 9.6.0
HIGH7.5Parse Server Vulnerable to Server-Side Request Forgery (SSRF) in File Upload via URI Format
>= 4.2.0, < 7.5.4, >= 8.0.0, < 8.4.0
HIGH7.5Parse Server may crash when uploading file without extension
>= 1.0.0, < 5.5.6, >= 6.0.0, < 6.3.1
HIGH7.5Trigger `beforeFind` not invoked in internal query pipeline in parse-server
from 0, < 5.5.5, >= 6.0.0, < 6.2.2
HIGH7.5Parse Server crashes when receiving file download request with invalid byte range
from 0, < 4.10.17, >= 5.0.0, < 5.2.8
HIGH7.5Invalid file request can crashe parse-server
from 0, < 4.10.12, >= 5.0.0, < 5.2.3
HIGH7.5Authentication bypass and denial of service (DoS) vulnerabilities in Apple Game Center auth adapter
from 0, < 4.10.10, >= 5.0.0, < 5.2.1
HIGH7.5Crash server with query parameter
from 0, < 4.10.3
HIGH7.2Parse Server subject to Prototype pollution via Cloud Code Webhooks
from 0, < 4.10.20, >= 5.0.0, < 5.3.3
HIGH7.2Parse Server Prototype pollution and Injection via Cloud Code Webhooks or Cloud Code Triggers
from 0, < 4.10.19, >= 5.0.0, < 5.3.2
MEDIUM6.9Parse Server has an OAuth login vulnerability
from 0, < 8.0.2
MEDIUM6.5Parse Server: LiveQuery bypasses CLP pointer permission enforcement
from 0, < 8.6.53, >= 9.0.0, < 9.6.0
MEDIUM6.3Parse Server vulnerable to phishing attack vulnerability that involves uploading malicious HTML file
from 0, < 5.4.4, >= 6.0.0, < 6.1.1
MEDIUM5.9Parse Server: LiveQuery subscription with invalid regular expression crashes server
from 0, < 8.6.43, >= 9.0.0, < 9.6.0
MEDIUM5.3Parse Server: Protected field change detection oracle via LiveQuery watch parameter
from 0, < 8.6.54, >= 9.0.0, < 9.6.0
MEDIUM5.3Parse Server: Email verification resend page leaks user existence
from 0, < 8.6.51, >= 9.0.0, < 9.6.0
MEDIUM5.3Parse Server exposes the data schema via GraphQL API
>= 5.3.0, < 8.2.2
MEDIUM4.3Parse Server's Endpoint `/sessions/me` bypasses `_Session` `protectedFields`
>= 7.0.0, < 8.6.75, >= 9.0.0, < 9.8.0
MEDIUM4.3Parse Server: Session update endpoint allows overwriting server-generated session fields
from 0, < 8.6.57, >= 9.0.0, < 9.6.0
MEDIUM4.3Parse Server session creation endpoint allows overwriting server-generated session fields
from 0, < 8.6.42, >= 9.0.0, < 9.6.0
MEDIUM4.3Parse Server subject to Incorrect Resource Transfer Between Spheres
from 0, < 4.10.15, >= 5.0.0, < 5.2.6
LOW3.7Parse Server has a login timing side-channel reveals user existence
from 0, < 8.6.74, >= 9.0.0, < 9.8.0
LOW3.7Parse Server subject to Improper Authentication allowing Auth adapter app ID validation to be circumvented
from 0, < 4.10.16, >= 5.0.0, < 5.2.7
—parse-server: LiveQuery discloses object data to a subscriber across an ACL read-access change
from 0, < 8.6.83, >= 9.0.0, < 9.9.1
—parse-server: Stored XSS via non-standard file extension bypassing file upload extension blocklist
from 0, < 8.6.81, >= 9.0.0, < 9.9.1
—Parse Server: Relation `$relatedTo` query bypasses `protectedFields` and owning-object ACL
from 0, < 8.6.80, >= 9.0.0, < 9.9.1
—Parse Server: Endpoints `/login` and `/verifyPassword` disclose MFA secrets and protected fields when `_User` get is denied
>= 9.8.0, < 9.9.1
—Parse Server: Stored XSS via trailing-dot filename bypassing file upload extension blocklist
from 0, < 8.6.79, >= 9.0.0, < 9.9.1
—Parse Server: Server option routeAllowList is bypassable through batch sub-requests
>= 9.8.0, < 9.9.1
—parse-server: Denial of service via exponential-time processing of deeply nested query operators
from 0, < 8.6.82, >= 9.0.0, < 9.9.1
—Parse Server: GraphQL "Did you mean" validation suggestions disclose schema to unauthenticated callers
from 0, < 8.6.78, >= 9.0.0, < 9.9.1
—Parse Server: Pre-authentication denial of service via client version header regex backtracking
from 0, < 8.6.77, >= 9.0.0, < 9.9.1
—Parse Server: MFA SMS one-time password accepted twice under concurrent login
from 0, < 8.6.76, >= 9.0.0, < 9.9.0
—Parse Server has a file upload Content-Type override via extension mismatch
from 0, < 8.6.73, >= 9.0.0, < 9.7.1
—Parse Server: Streaming file download bypasses afterFind file trigger authorization
from 0, < 8.6.71, >= 9.0.0, < 9.7.1
—Parse Server: LiveQuery protected-field guard bypass via array-like logical operator value
from 0, < 8.6.70, >= 9.0.0, < 9.7.0
—Parse Server: Session field immutability bypass via falsy-value guard
from 0, < 8.6.69, >= 9.0.0, < 9.7.0
—Parse Server: GraphQL complexity validator exponential fragment traversal DoS
from 0, < 8.6.68, >= 9.0.0, < 9.7.0
—Parse Server: Cloud function validator bypass via prototype chain traversal
from 0, < 8.6.67, >= 9.0.0, < 9.7.0
—Parse Server: GraphQL API endpoint ignores CORS origin restriction
from 0, < 8.6.66, >= 9.0.0, < 9.7.0
—Parse Server: LiveQuery protected field leak via shared mutable state across concurrent subscribers
from 0, < 8.6.65, >= 9.0.0, < 9.7.0
—Parse Server: MFA single-use token bypass via concurrent authData login requests
from 0, < 8.6.64, >= 9.0.0, < 9.7.0
—Parse Server: Auth data exposed via verify password endpoint
from 0, < 8.6.63, >= 9.0.0, < 9.7.0
—Parse Server: Auth data exposed via /users/me endpoint
from 0, < 8.6.61, >= 9.0.0, < 9.6.0
—Parse Server: MFA recovery code single-use bypass via concurrent requests
from 0, < 8.6.60, >= 9.0.0, < 9.6.0
—Parse Server: SQL injection via aggregate and distinct field names in PostgreSQL adapter
from 0, < 8.6.59, >= 9.0.0, < 9.6.0
—Parse Server: Denial of service via unindexed database query for unconfigured auth providers
from 0, < 8.6.58, >= 9.0.0, < 9.6.0
—Parse Server leaks protected fields via LiveQuery afterEvent trigger
from 0, < 8.6.50, >= 9.0.0, < 9.6.0
—Parse Server affected by empty authData bypassing credential requirement on signup
from 0, < 8.6.49, >= 9.0.0, < 9.6.0
—Parse Server vulnerable to schema poisoning via prototype pollution in deep copy
from 0, < 8.6.44, >= 9.0.0, < 9.6.0
—Parse Server's Cloud function dispatch crashes server via prototype chain traversal
from 0, < 8.6.47, >= 9.0.0, < 9.6.0
—Parse Server has a password reset token single-use bypass via concurrent requests
from 0, < 8.6.48, >= 9.0.0, < 9.6.0
—Parse Server crash via deeply nested query condition operators
from 0, < 8.6.45, >= 9.0.0, < 9.6.0
—Parse Server has a stored XSS filter bypass via Content-Type MIME parameter and missing XML extension blocklist entries
from 0, < 8.6.41, >= 9.0.0, < 9.6.0
—Parse Server GraphQL WebSocket endpoint bypasses security middleware
from 0, < 8.6.40, >= 9.0.0, < 9.6.0
—Parse Server OAuth2 adapter app ID validation sends wrong token to introspection endpoint
>= 8.0.2, < 8.6.39, >= 9.0.0, < 9.6.0
—Parse Server: Account takeover via operator injection in authentication data identifier
from 0, < 8.6.38, >= 9.0.0, < 9.6.0
—Parse Server OAuth2 adapter shares mutable state across providers via singleton instance
from 0, < 8.6.37, >= 9.0.0, < 9.6.0
—Parse Server has a SQL injection via query field name when using PostgreSQL
from 0, < 8.6.36, >= 9.0.0, < 9.6.0
—Parse Server has a protected fields bypass via LiveQuery subscription WHERE clause
from 0, < 8.6.35, >= 9.0.0, < 9.6.0
—Parse Server has user enumeration via email verification endpoint
from 0, < 8.6.34, >= 9.0.0, < 9.6.0
—Parse Server MFA recovery codes not consumed after use
from 0, < 8.6.33, >= 9.0.0, < 9.6.0
—Parse Server has a protected fields bypass via dot-notation in query and sort
from 0, < 8.6.32, >= 9.0.0, < 9.6.0
—Parse Server has a SQL Injection via dot-notation sub-key name in `Increment` operation on PostgreSQL
from 0, < 8.6.31, >= 9.0.0, < 9.6.0
—Parse Server has Stored XSS via file upload of HTML-renderable file types
from 0, < 8.6.30, >= 9.0.0, < 9.6.0
—Parse Server has a SQL injection via `Increment` operation on nested object field in PostgreSQL
from 0, < 8.6.29, >= 9.0.0, < 9.6.0
—Parse Server has an LDAP injection via unsanitized user input in DN and group filter construction
from 0, < 8.6.26, >= 9.0.0, < 9.5.2
—Parse Server: Classes `_GraphQLConfig` and `_Audience` master key bypass via generic class routes
from 0, < 8.6.25, >= 9.0.0, < 9.5.2
—Parse Server has a rate limit bypass via batch request endpoint
from 0, < 8.6.23, >= 9.0.0, < 9.5.2
—Parse Server OAuth2 authentication adapter account takeover via identity spoofing
from 0, < 8.6.22, >= 9.0.0, < 9.5.2
—Parse Server session token exfiltration via `redirectClassNameForKey` query parameter
from 0, < 8.6.21, >= 9.0.0, < 9.5.2
—Parse Server has a protected fields bypass via logical query operators
from 0, < 8.6.19, >= 9.0.0, < 9.5.2
—Parse Server is missing audience validation in Keycloak authentication adapter
from 0, < 8.6.18, >= 9.0.0, < 9.5.2
—Parse Server has stored cross-site scripting (XSS) via SVG file upload
from 0, < 8.6.17, >= 9.0.0, < 9.5.2
—Parse Server ha a bypass of class-level permissions in LiveQuery
from 0, < 8.6.16, >= 9.0.0, < 9.5.2
—Parse Server affected by denial-of-service via unbounded query complexity in REST and GraphQL API
from 0, < 8.6.15, >= 9.0.0, < 9.5.2
—Parse Server has a NoSQL injection via token type in password reset and email verification endpoints
from 0, < 8.6.14, >= 9.0.0, < 9.5.2
—Parse Server has a SQL injection via dot-notation field name in PostgreSQL
from 0, < 8.6.28, >= 9.0.0, < 9.6.0
—Parse Server has Denial of Service (DoS) and Cloud Function Dispatch Bypass via Prototype Chain Resolution
from 0, < 8.6.13, >= 9.0.0, < 9.5.1
—Parse Server has denylist `requestKeywordDenylist` keyword scan bypass through nested object placement
from 0, < 8.6.12, >= 9.0.0, < 9.5.1
—Parse Server affected by Regular Expression Denial of Service (ReDoS) via `$regex` query in LiveQuery
from 0, < 8.6.11, >= 9.0.0, < 9.5.0
—Parse Server: JWT audience validation bypass in Google, Apple, and Facebook authentication adapters
from 0, < 9.5.0
—Parse Server: GraphQL `__type` introspection bypass via inline fragments when public introspection is disabled
>= 9.3.1, < 9.5.0
—Parse Server: File metadata endpoint bypasses `beforeFind` / `afterFind` trigger authorization
from 0, < 9.5.0
—Parse Server: `PagesRouter` path traversal allows reading files outside configured pages directory
from 0, < 9.5.0
—Parse Server: Malformed `$regex` query leaks database error details in API response
from 0, < 9.5.0
—Parse Server: Endpoint `/loginAs` allows `readOnlyMasterKey` to gain full read and write access as any user
from 0, < 9.5.0
—Parse Server: File creation and deletion bypasses `readOnlyMasterKey` write restriction
from 0, < 9.5.0
—Parse Server: Cloud Hooks and Cloud Jobs bypass `readOnlyMasterKey` write restriction
from 0, < 9.4.1
—Parse Server: Account takeover via JWT algorithm confusion in Google auth adapter
from 0, < 8.6.3, >= 9.0.0, < 9.3.1
—Parse Server GitHub CI workflow vulnerable to RCE through Improper Privilege Management
from 0, < 8.6.0
—Parse Server has Server-Side Request Forgery (SSRF) in Instagram OAuth Adapter
from 0, < 8.6.2, >= 9.0.0, < 9.1.1
—Parse Server vulnerable to Cross-Site Scripting (XSS) via Unescaped Mustache Template Variables
from 0, < 8.6.1, >= 9.0.0, < 9.1.0
—Parse Server allows public `explain` queries which may expose sensitive database performance information and schema details
from 0, < 8.5.0